Hackers Use AI Malware to Break Into Brazilian Banks and Make Fraudulent Transfers
Brief
Brazilian financial organizations are facing a growing threat from a cybercrime group tracked as BREEZE COMET. Since 2024, Mandiant has investigated attacks against financial services, retail, and eCommerce companies in Brazil.
The group is financially motivated and focuses on breaking into systems that can process payments. BREEZE COMET, previously known as UNC5669, is linked to activity reported as Plump Spider and SHADOW-AETHER-064.
Its goal is not ordinary banking fraud against individual customers. Instead, it attempts to compromise organizations that have direct access to banking software, payment APIs, and Brazil’s payment infrastructure.
The attackers target banks, payment processors, fintech firms, exchanges, retailers, and banking-software providers. They seek access to systems connected to Pix, STR, Boleto, and other transaction platforms.
